<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T03:54:51.810874+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</id>
    <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-04T03:54:52.603430+00:00</updated>
    <content>certfr-2026-avi-1094</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366121</id>
    <title>EUVD-2026-366121</title>
    <updated>2026-10-04T03:54:52.603508+00:00</updated>
    <content>EUVD-2026-366121</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366121"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44990</id>
    <title>fkie_cve-2026-44990</title>
    <updated>2026-10-04T03:54:52.603525+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` path and can lead to stored XSS in applications that render sanitized output back to users. Version 2.17.4 patches the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44990"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rpr9-rxv7-x643</id>
    <title>GHSA-rpr9-rxv7-x643 — Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`</title>
    <updated>2026-10-04T03:54:52.603563+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: sanitize-html</p>
<p>### Summary
Under the default configuration, `sanitize-html` can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` path and can lead to stored XSS in applications that render sanitized output back to users.</p>
<p>### Details
In `sanitize-html@2.17.3`, the default `nonTextTags` list includes only `script`, `style`, `textarea`, and `option` in `index.js` lines 138-142. That means disallowed `xmp` tags are not treated as "drop the entire contents" tags.</p>
<p>Later, in the `ontext` handler at `index.js` lines 569-577, the code special-cases `textarea` and `xmp` and appends their text content directly to the output without escaping:</p>
<p>```js
} else if ((options.disallowedTagsMode === 'discard' || options.disallowedTagsMode === 'completelyDiscard') &amp;&amp; (tag === 'textarea' || tag === 'xmp')) {
  result += text;
}
```</p>
<p>Because `htmlparser2` treats `xmp` as a raw-text element, markup inside `xmp` is parsed as text on input but becomes live markup again once it is appended unescaped to the sanitized output.</p>
<p>This creates a default sanitizer bypass. For example, a disallowed `&lt;xmp&gt;` wrapper can be used to smuggle `&lt;script&gt;` or event-handler payloads through sanitization.</p>
<p>The README also appears to contradict the implementation. In the "Discarding the entire contents of a disallowed tag" section, the documented exception list names only `style`, `script`, `textarea`, and `option…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rpr9-rxv7-x643"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11436-1</id>
    <title>openSUSE-SU-2026:11436-1 — golang-github-prometheus-prometheus-3.13.2-1.1 on GA media</title>
    <updated>2026-10-04T03:54:52.603613+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang-github-prometheus-prometheus-3.13.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11436-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:36882</id>
    <title>RHSA-2026:36882 — Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.14.3 security update</title>
    <updated>2026-10-04T03:54:52.603635+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>lodash: prototype pollution in _.unset and _.omit functions database/sql: Postgres Scan Race Condition Apache Thrift: c_glib: Apache Thrift c_glib: Denial of Service via specially crafted requests golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects angular: Angular: Cross-site scripting vulnerability in Template Compiler axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution github.com/buger/jsonparser: github.com/buger/jsonparser: Denial of Service via malformed JSON input google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/russellhaering/goxmldsig: goxmlsig: Integrity bypass due to incorrect XML Digital Signature validation via loop variable capture issue axios: Axios: Remote Code Execution via Prototype Pollution escalation OpenFGA: github.com/openfga/openfga: OpenFGA: Information disclosure of preshared API…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:36882"/>
  </entry>
</feed>
